CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8771
4.3 MEDIUM

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data …

Sep 26, 2024
CVE-2024-7259
4.9 MEDIUM

A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools …

Sep 26, 2024
CVE-2024-46632
4.3 MEDIUM

Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function.

Sep 26, 2024
CVE-2024-45983
6.3 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerability allows an attacker to craft a malicious HTML form …

Sep 26, 2024
CVE-2024-43191
7.2 HIGH

IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.

Sep 26, 2024
CVE-2024-41605
8.4 HIGH

In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan …

Sep 26, 2024
CVE-2024-39319
5.3 MEDIUM

aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, an insecure direct object reference allows …

Sep 26, 2024
CVE-2024-9155
4.3 MEDIUM

Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have not been linked to a …

Sep 26, 2024
CVE-2024-30134
6.7 MEDIUM

The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application.

Sep 26, 2024
CVE-2024-9177
6.4 MEDIUM

The Themedy Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themedy_col, themedy_social_link, themedy_alertbox, and themedy_pullleft shortcodes in all versions up …

Sep 26, 2024
CVE-2024-46330
7.4 HIGH

VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun object.

Sep 26, 2024
CVE-2024-46329
8.0 HIGH

VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object.

Sep 26, 2024
CVE-2024-46328
8.0 HIGH

VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts, including root.

Sep 26, 2024
CVE-2024-46327
5.7 MEDIUM

An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a directory traversal.

Sep 26, 2024
CVE-2024-31899
4.3 MEDIUM

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device.

Sep 26, 2024
CVE-2023-46175
4.4 MEDIUM

IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which can be read by …

Sep 26, 2024
CVE-2024-8633
5.5 MEDIUM

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions …

Sep 26, 2024
CVE-2024-7108
9.8 CRITICAL

Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CyberMath: before CYBM.240816253.

Sep 26, 2024
CVE-2024-7107
7.5 HIGH

Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath allows Collect Data from Common Resource Locations.This issue affects CyberMath: …

Sep 26, 2024
CVE-2024-8725
6.8 MEDIUM

Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to …

Sep 26, 2024
CVE-2024-8704
7.2 HIGH

The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' …

Sep 26, 2024
CVE-2024-8126
7.5 HIGH

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. …

Sep 26, 2024
CVE-2024-9199
5.8 MEDIUM

Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the victim in a short …

Sep 26, 2024
CVE-2024-9198
7.6 HIGH

Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image …

Sep 26, 2024
CVE-2024-9173
6.4 MEDIUM

The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 …

Sep 26, 2024
CVE-2024-9127
6.4 MEDIUM

The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignment’ parameter in all versions up to, and including, 3.0.0 due …

Sep 26, 2024
CVE-2024-9125
6.4 MEDIUM

The king_IE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to …

Sep 26, 2024
CVE-2024-9117
6.4 MEDIUM

The Mapplic Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due …

Sep 26, 2024
CVE-2024-9115
6.4 MEDIUM

The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Sep 26, 2024
CVE-2022-4541
7.2 HIGH

The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value in versions up to, and including, 1.0 …

Sep 26, 2024
CVE-2024-9025
5.3 MEDIUM

The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on …

Sep 26, 2024
CVE-2024-8872
6.1 MEDIUM

The Store Hours for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Sep 26, 2024
CVE-2024-47337
4.3 MEDIUM

Missing Authorization vulnerability in Phillip Dane Joy Of Text Lite joy-of-text.This issue affects Joy Of Text Lite: from n/a through <= 2.3.1.

Sep 26, 2024
CVE-2024-47044
5.3 MEDIUM

Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this …

Sep 26, 2024
CVE-2024-8861
6.4 MEDIUM

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 …

Sep 26, 2024
CVE-2024-47197
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This issue affects Maven Archetype Plugin: from …

Sep 26, 2024
CVE-2024-47145
3.1 LOW

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view …

Sep 26, 2024
CVE-2024-47003
3.1 LOW

Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an …

Sep 26, 2024
CVE-2024-45843
3.1 LOW

Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to …

Sep 26, 2024
CVE-2024-42406
5.4 MEDIUM

Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is …

Sep 26, 2024
CVE-2024-4278
5.5 MEDIUM

An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and …

Sep 26, 2024
CVE-2024-6517
6.1 MEDIUM

The Contact Form 7 Math Captcha WordPress plugin through 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading …

Sep 26, 2024
CVE-2024-0133
4.1 MEDIUM

NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files …

Sep 26, 2024
CVE-2024-0132
9.0 CRITICAL

NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain …

Sep 26, 2024
CVE-2024-7781
8.1 HIGH

The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper …

Sep 26, 2024
CVE-2024-7772
9.8 CRITICAL

The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function in …

Sep 26, 2024
CVE-2024-45836
6.1 MEDIUM

Cross-site scripting vulnerability exists in the web management page of PLANEX COMMUNICATIONS network cameras. If a logged-in user accesses a specific file, an arbitrary script …

Sep 26, 2024
CVE-2024-45372
6.5 MEDIUM

MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of …

Sep 26, 2024
CVE-2024-47045
7.8 HIGH

Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, a malicious DLL prepared by an attacker may be …

Sep 26, 2024
CVE-2023-52950
5.3 MEDIUM

Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent man-in-the-middle attackers to obtain user …

Sep 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.